All posts by jzb

[$] LWN.net Weekly Edition for March 5, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1060392/

Inside this week’s LWN.net Weekly Edition:

  • Front: Python’s bitwise-inversion operator; atomic buffered I/O; keeping open source open; Magit and Majutsu; IIIF; free software and free tools.
  • Briefs: Ad tracking; firmware updates; TCP zero-copy; Motorola GrapheneOS phones; Gram 1.0; groff 1.24.0; Texinfo 7.3; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1061295/

Security updates have been issued by AlmaLinux (container-tools:rhel8, firefox, go-rpm-macros, kernel, kernel-rt, mingw-fontconfig, nginx:1.24, thunderbird, and valkey), Debian (gimp), Fedora (apt, avr-binutils, keylime, keylime-agent-rust, perl-Crypt-URandom, python-apt, and rsync), Red Hat (go-rpm-macros and yggdrasil-worker-package-manager), Slackware (python3), SUSE (busybox, cosign, cups, docker, evolution-data-server, freerdp, glibc, gnome-remote-desktop, go1.24-openssl, go1.25-openssl, govulncheck-vulndb, libpng16, libsoup, libssh, libxml2, patch, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python, python311, rust-keylime, smc-tools, tracker-miners, and zlib), and Ubuntu (curl, imagemagick, intel-microcode, linux, linux-aws, linux-kvm, linux-aws, linux-aws-5.15, linux-gcp-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15, linux-aws-fips, and linux-raspi, linux-raspi-5.4).

[$] Free software needs free tools

Post Syndicated from jzb original https://lwn.net/Articles/1060649/

One of the contradictions of the modern open-source movement is
that projects which respect user freedoms often rely on proprietary
tools that do not: communities often turn to non-free software for
code hosting, communication, and more. At Configuration Management
Camp
(CfgMgmtCamp) 2026, Jan Ainali spoke
about
the need for open-source projects to adopt open tools;
he hoped to persuade new and mature projects to switch to open
alternatives, even if just one tool, to reduce their dependencies on
tech giants and support community-driven infrastructure.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1061043/

Security updates have been issued by AlmaLinux (containernetworking-plugins, gnutls, kernel, libpng, and skopeo), Debian (firefox-esr, php8.2, and spip), Fedora (erlang and python-pillow), Red Hat (go-toolset:rhel8, golang, and yggdrasil), SUSE (cups, fluidsynth, gvfs, haproxy, libsoup, libsoup-3_0-0, mozilla-nss, python-azure-core, and shim), and Ubuntu (git and mailman).

[$] The exploitation paradox in open source

Post Syndicated from jzb original https://lwn.net/Articles/1058031/

The free and open-source software (FOSS) movements have always been
about giving freedom and power to individuals and organizations;
throughout that history, though, there have also been actors trying
to exploit FOSS to their own advantage. At Configuration Management
Camp
(CfgMgmtCamp) 2026 in Ghent, Belgium, Richard Fontana described
the “exploitation paradox” of open source: the recurring
pattern of crises when actors exploit loopholes to restrict freedoms
or gain the upper hand over others in the community. He also talked
about the attempts to close those loopholes as well as the need to
look beyond licenses as a means of keeping freedom alive.

Gram 1.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1060912/

Version
1.0
of Gram, an “opinionated fork of the Zed code editor“,
has been released. Gram removes telemetry, AI features, collaboration
features, and more. It adds built-in documentation, support for
additional languages, and tab-completion features similar to the Supertab
plugin for Vim. The mission statement for
the project explains:

At first, I tried to build some other efforts I found online to
make Zed work without the AI features just so I could check it out,
but didn’t manage to get them to work. At some point, the curiosity
turned into spite. I became determined to not only get the editor to
run without all of the misfeatures, but to make it a full-blown fork
of the project. Independent of corporate control, in the spirit of Vim
and the late Bram Moolenaar who could have added subscription fees and
abusive license agreements had he so wanted, but instead gave his work
as a gift to the world and asked only for donations to a good cause
close to his heart in return.

This is the result. Feel free to build it and see if it works for
you. There is no license agreement or subscription beyond the open
source license of the code (GPLv3). It is yours now, to do with as you
please.

According to a blog
post
on the site, the plan for the editor is to diverge from Zed
and proceed slowly.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1060911/

Security updates have been issued by Debian (lxd, orthanc, and thunderbird), Fedora (cef, chromium, gimp, nextcloud, pgadmin4, python-django4.2, python-django5, python3-docs, python3.12, python3.13, and python3.9), Oracle (container-tools:rhel8 and mingw-fontconfig), Slackware (gvfs, mozilla, and telnet), SUSE (avahi, cockpit-356, cockpit-podman, cockpit-podman-120, containerized-data-importer, digger-cli, docker, evolution-data-server, expat, firefox, freerdp2, gimp, glib2, glibc, go1, google-guest-agent, google-osconfig-agent, gosec, gpg2, heroic-games-launcher, ImageMagick, kernel, kernel-firmware, kubevirt, libIex-3_4-33, libjxl-devel, libpng16, libsodium, libsoup, libsoup2, libssh, libudisks2-0, libwireshark19, protobuf, python-pyasn1, python-urllib3, python311, python311-Flask, rust-keylime, thunderbird, ucode-intel, and valkey), and Ubuntu (git).

Two new stable kernels, possible regression

Post Syndicated from jzb original https://lwn.net/Articles/1060646/

Greg Kroah-Hartman has announced the 6.19.4 and 6.18.14 stable kernels. Shortly after
6.19.4 was released Kris Karas reportedgetting a repeatable Oops right
when networking is initialized, likely when nft is loading its
ruleset
“; the problem did not appear to be present in 6.18.14. Users
of nftables may wish to hold off on upgrades to 6.19.4 for now. We
will provide updates as they are available.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1060645/

Security updates have been issued by AlmaLinux (389-ds-base, buildah, firefox, freerdp, golang-github-openprinting-ipp-usb, grafana-pcp, kernel, libpng15, munge, nodejs:20, nodejs:22, podman, protobuf, python-pyasn1, runc, and skopeo), Debian (chromium, nss, and python-django), Fedora (firefox, freerdp, gh, libmaxminddb, nss, python3.15, and udisks2), Oracle (buildah, firefox, freerdp, kernel, libpng, podman, python-pyasn1, skopeo, and valkey), Red Hat (container-tools:rhel8), SUSE (autogen, chromium, cockpit, cockpit-machines-348, cockpit-packages, cockpit-repos, cockpit-subscriptions, crun, docker, docker-compose, docker-stable, erlang, freerdp, frr, glib2, gpg2, kernel, kernel-firmware, libsodium, libsoup, libsoup2, openvswitch, python, python-pyasn1, python-urllib3, python-urllib3_1, python3, qemu, redis7, regclient, and ucode-intel), and Ubuntu (linux-aws, linux-aws-6.8, linux-ibm, linux-ibm-6.8, linux-xilinx, python-authlib, and ruby-rack).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1060391/

Security updates have been issued by AlmaLinux (freerdp), Debian (firefox-esr and libstb), Fedora (389-ds-base, chromium, firefox, munge, opentofu, python3-docs, python3.14, and vim), Oracle (buildah, containernetworking-plugins, gimp, grafana, grafana-pcp, kernel, podman, runc, and skopeo), Red Hat (go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, mariadb:10.11, podman, and skopeo), SUSE (cacti, docker-stable, expat, firefox-esr, freerdp, freerdp2, libjxl, libsoup-2_4-1, python-tornado, python-urllib3_1, python3, python311-Django4, python312, python313, python39, and redis), and Ubuntu (ceph, mongodb, protobuf, and rlottie).

[$] LWN.net Weekly Edition for February 26, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1059501/

Inside this week’s LWN.net Weekly Edition:

  • Front: New flags for clone3(); Discord replacements; virtual swap spaces; BPF memory protection keys; PostgreSQL’s lessons in attracting contributors; 7.0 merge window; Network Time Security.
  • Briefs: OpenSUSE governance; Firefox 148.0; GNU Awk 5.4.0; GNU Octave 11.1.0; Rust in Ladybird; LibreOffice Online; Weston 15.0; RIP Robert Kaye; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] An effort to secure the Network Time Protocol

Post Syndicated from jzb original https://lwn.net/Articles/1059200/

The Network Time
Protocol
(NTP) debuted in 1985; it is a universally used, open
specification that is deeply important for all sorts of activities we
take for granted. It also, despite a number of efforts, remains
stubbornly unsecured. Ruben Nijveld presented work at FOSDEM 2026 to
speed adoption of the thus-far largely ignored standard for securing
NTP traffic: IETF’s RFC-8915 that specifies Network Time
Security
(NTS) for NTP.

MetaBrainz mourns the loss of Robert Kaye

Post Syndicated from jzb original https://lwn.net/Articles/1060189/

The MetaBrainz Foundation has announced the unexpected passing of
its founder and executive director, Robert Kaye:

Robert’s vision and leadership shaped MetaBrainz and left a lasting
mark on the music industry and open source movement. His contributions
were significant and his loss is deeply felt across our global
community.

The Board is actively overseeing a smooth leadership transition and
has measures in place to ensure that MetaBrainz continues to operate
without interruption. Further updates will be shared in due
course.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1060185/

Security updates have been issued by AlmaLinux (grafana and grafana-pcp), Debian (gnutls28), Fedora (chromium and yt-dlp), Oracle (389-ds-base, kernel, munge, and openssl), Red Hat (buildah, containernetworking-plugins, opentelemetry-collector, podman, runc, and skopeo), Slackware (mozilla), SUSE (chromium, cosign, firefox, freerdp, gimp, heroic-games-launcher, kernel, libopenssl-3-devel, libxml2, libxslt, mosquitto, openqa, os-autoinst, openqa-devel-container, openvswitch, phpunit, postgresql14, postgresql15, postgresql16, protobuf, python310, python311-PyPDF2, python36, snpguest, warewulf4, and weblate), and Ubuntu (curl, kernel, linux, linux-gcp, linux-gke, linux-gkeop, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia-tegra, linux-oracle, linux-xilinx-zynqmp, linux, linux-gkeop, linux-hwe-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-raspi, linux-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gke, linux-oracle-6.8, linux-gcp-fips, linux-ibm, linux-ibm-6.8, linux-intel-iot-realtime, linux-realtime, linux-raspi-realtime, linux-realtime, linux-realtime-6.8, and linux-xilinx).

GNU Awk 5.4.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1060050/

Version
5.4.0
of GNU awk
(gawk) has been released. This is a major release with a change in
gawk’s default regular-expression matcher: it now uses MinRX
as the default regular-expression engine.

This matcher is fully POSIX compliant, which the current GNU matchers
are not. In particular it follows POSIX rules for finding the longest
leftmost submatches. It is also more strict as to regular expression
syntax, but primarily in a few corner cases that normal, correct,
regular expression usage should not encounter.

Because regular expression matching is such a fundamental part of
awk/gawk, the original GNU matchers are still included in gawk. In order
to use them, give a value to the GAWK_GNU_MATCHERS environment variable
before invoking gawk.

[…] The original GNU matchers will eventually be removed from
gawk. So, please take the time to notice and report any issues in the
MinRX matcher, so that they can be ironed out sooner rather than later.

See the release announcement for additional changes.

Firefox 148.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1060047/

Version
148
of Firefox has been released. The most notable change in this
release is the addition of a “Block AI enhancements” option that
allows turning off “new or current AI enhancements in Firefox, or
pop-ups about them
” with a single toggle.

With this release, Firefox now supports the Trusted
Types API
to help prevent cross-site scripting attacks as well as
the Sanitizer
API
that provides new methods for HTML manipulation. See the release
notes for developers
for changes that may affect web developers or
those who create Firefox add-ons.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1060018/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, and munge), Debian (openssl), Mageia (gegl), Oracle (firefox, freerdp, gnupg2, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, java-11-openjdk, kernel, libpng15, munge, nodejs:20, nodejs:22, protobuf, and uek-kernel), SUSE (libpng12, libpng16, and openQA, openQA-devel-container, os-autoinst), and Ubuntu (gimp, libssh, and linux-azure).

[$] Lessons on attracting new contributors from 30 years of PostgreSQL

Post Syndicated from jzb original https://lwn.net/Articles/1058831/

The PostgreSQL project has been
chugging along for decades; in that time, it has become a thriving open-source
project, and its participants have learned a thing or two about what works in
attracting new contributors. At FOSDEM 2026, PostgreSQL contributor Claire
Giordano shared some of the lessons learned and where the project is still
struggling. The lessons might be of interest to others who are thinking about
how their own projects can evolve.